Is Your Backup Clean? Ransomware Can Encrypt Backups Too

When ransomware locks a facility's files, the first question is always the same: do we have a clean backup? Too many organizations find out the hard way that the answer is not as simple as yes. Backups can be encrypted along with everything else, stored on the same network, or never tested at all.

This explainer covers a widely used guideline, the 3-2-1 rule, and the practical steps that make backups useful when you need them most.

What the 3-2-1 rule means

The rule is easy to remember:

Keep at least three copies of your important data: the original and two backups.

Store them on two different types of media or systems, such as a local appliance and a cloud service.

Keep one copy offsite, away from your building and your main network.

Many security teams now extend this with an additional idea: at least one copy should be offline or immutable, meaning it cannot be changed or deleted for a set period, even by an administrator.

Why ordinary backups can fail

Modern ransomware often targets backups directly. Attackers look for backup servers, network shares and cloud credentials. Common weak points include:

A backup drive permanently connected to the main network.

Backup software running with an account that has broad administrator rights.

Cloud sync tools that faithfully copy encrypted files over the good ones.

No monitoring, so nobody notices backups have been failing for weeks.

Backups that cover servers but not the laptops, cloud accounts or devices that also hold important data.

File sync services are not true backups. If a file is deleted or encrypted, the change may sync everywhere.

Decide what to back up

Start by listing the systems and data that your operation depends on:

The electronic health record, if hosted locally or if you export data from it.

File servers and shared drives containing policies, schedules and records.

Email and calendar data.

Databases for billing, scheduling and payroll.

Configuration files for network equipment and firewalls.

Phone system and door access settings.

If a vendor hosts a system, ask in writing how they back it up and how quickly they can restore it.

Set recovery targets in plain terms

Two questions guide the design:

How much recent work can we afford to lose? This is your recovery point. If the answer is a few hours, backups must run frequently.

How long can we operate without this system? This is your recovery time. If medication administration depends on it, the answer is very short.

Write these answers down for each system. They drive your choices about technology and cost.

Protect the backups themselves

Use separate credentials for backup systems, with multi-factor authentication.

Enable immutability or retention locks where your backup product supports it.

Encrypt backups in transit and at rest, which also supports HIPAA safeguards for electronic protected health information.

Keep one copy offline or in a location that normal accounts cannot reach.

Limit who can delete or change backup settings.

Test your restores

The most overlooked step is restoring. A backup you have never restored is a hope, not a plan. Build a schedule:

Monthly, restore a few files and confirm they open.

Quarterly, restore a full server or system into a test environment.

Yearly, run a larger exercise that simulates losing a key system and time how long recovery takes.

Record the results. The HIPAA Security Rule calls for a data backup plan, a disaster recovery plan and an emergency mode operation plan, and testing records help show those plans are real.

Monitor and alert

Backups should send alerts when they fail or when something looks unusual, such as a sudden spike in changed files. Someone must be responsible for reading those alerts. A failed job that nobody sees is as bad as no backup.

Do not forget the human side

Document where backup credentials are stored, who can perform a restore and who to call after hours. Keep a printed copy of recovery instructions because digital copies may be unavailable during an outage.

How UnityCare IT helps

UnityCare IT helps healthcare and senior-living providers design, monitor and test backup and recovery. If you are not sure whether your current backups would survive a ransomware attack, we can help you check.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034